logo

New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems

ID: c8b3d524-b546-506a-9564-aa1e480fcd94

STIX ID: report--c8b3d524-b546-506a-9564-aa1e480fcd94

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-01-11

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Security researchers released a cross-platform proof-of-concept that exploits CVE-2023-51467 in Apache OFBiz (CVSS 9.8) to execute memory-resident payloads and obtain remote shells by abusing groovy.util.Eval, enabling stealthy in-memory code execution on Windows and Linux; the flaw has been patched in Apache OFBiz 18.12.11 but threat actors have been observed attempting exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.